CVE-2026-0866General

HIGH

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Rejected reason: After the publication of the PoC by the researcher and further analysis, we have determined that this issue does not constitute a valid vulnerability. The technique described is an obfuscation method and does not bypass or impact any implicit or explicit security controls.

7.3/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 34 mentions across 11 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 17 signals
  • General: 15 classified signals
  • Disclosure: 12 classified signals
  • Peaked 10d ago at 8 mentions (2026-03-10); latest day: 1
  • 34 total mentions across 11 days

Deep dive

Activity timeline34 mentions / 11d
02468Mentions · 2026-03-10: 8Mentions · 2026-03-11: 8Mentions · 2026-03-12: 4Mentions · 2026-03-13: 4Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 3Mentions · 2026-03-19: 2Mentions · 2026-04-05: 1Mentions · 2026-06-06: 1PoC Mentioned / Linked · 2026-03-11: 1PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-19: 1Exploit Tool / Code · 2026-03-11: 1Exploit Tool / Code · 2026-03-17: 1Active Exploitation · 2026-03-10: 1Technical Details · 2026-03-10: 8Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 203-1003-1103-1203-1303-1403-1603-1703-1803-1904-0506-06
Signal classification5 categories
General
1544.1%
Disclosure
1235.3%
PoC
38.8%
False Positive
38.8%
Active Exploitation
12.9%
Referenced assets22 URLs
Classification over time
DateTotalLabels
2026-03-108
Active Exploitation1Disclosure7
2026-03-118
Disclosure1General6PoC1
2026-03-124
Disclosure1False Positive1General2
2026-03-134
General3PoC1
2026-03-141
General1
2026-03-161
General1
2026-03-171
PoC1
2026-03-183
Disclosure2General1
2026-03-192
False Positive2
2026-04-051
Disclosure1
2026-06-061
General1
Full discourse20 posts
  • blackorbird@blackorbird
    PoC

    ZIP format confusion technique that evades 98% of antivirus engines. Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload. CVE-2026-0866 https://github.com/bombadil-systems/zombie-zip https://t.co/KD9eE7o8lO

    Post summary

    The post announces CVE-2026-0866, provides a method that tricks antivirus engines, and shares a GitHub repository demonstrating the proof‑of‑concept exploitation tool. No signs of active exploitation or mitigation are noted.

    773126715518.9K
    40.6K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    ⚠️ CERT/CC warns a ZIP flaw tracked as CVE-2026-0866 lets attackers hide malware using malformed archive headers. Security tools trust the header and miss the payload, while it can still be extracted and executed with the right method. It breaks how AV and EDR validate files. 🔗 How Zombie ZIP bypasses detection and runs payloads → https://thehackernews.com/2026/03/threatsday-bulletin-oauth-trap-edr.html#zip-evasion-technique

    Post summary

    CERT/CC warns that CVE-2026-0866, a ZIP flaw involving malformed archive headers, lets attackers hide malware in ZIP files, potentially bypassing AV and EDR validation.

    34821354113.8K
    1.1M followersView on X
  • SANS.edu Internet Storm Center@sans_isc
    General

    Analyzing "Zombie Zip" (CVE-2026-0866) https://isc.sans.edu/diary/32786 https://t.co/0fU6vLrtwP

    Post summary

    The tweet references an analysis of CVE-2026-0866 but provides no details on exploitation, patching, or technical specifics.

    015145225.3K
    116.8K followersView on X
  • Es Geeks@EsGeeks
    PoC

    Zombie ZIP (CVE-2026-0866): evade detección en 98% de antivirus declarando Method=0 (Stored) pero usando DEFLATE real. PoC educativo para analizar fallos en parsers de ZIP. 🕵️‍♂️🔍🛡️ #ZombieZIP #Ciberseguridad #HackingEtico #EvasionAV #Privacidad #ZIP #CVE #antivirus #VirusTotal https://t.co/8QzXUL2Itg

    Post summary

    The tweet presents an educational proof‑of‑concept for CVE‑2026‑0866, detailing an AV evasion technique without evidence of active exploitation or official patches.

    030256769
    20.9K followersView on X
  • Ben@polygonben
    General

    How does this technique have CVE-2026-0866 assigned to it? Is this really a vulnerability? https://t.co/pa71rqTRJX

    Post summary

    The tweet questions the legitimacy of CVE-2026-0866, provides a link but no concrete technical details, exploit code, or mitigation steps.

    3201241.8K
    1.5K followersView on X
  • Nicolas Krassas@Dinosn
    False Positive

    CVE-2026-0866 "Zombie ZIP" unrealistic scenario is rejected from CVE. Thanks to CVE authorities for removing it, this was an invalid scenario that made a lot of noise in media without being an actual case. https://nvd.nist.gov/vuln/detail/CVE-2026-0866

    Post summary

    The post confirms that CVE‑2026‑0866, dubbed 'Zombie ZIP', was deemed invalid and removed from the CVE database.

    0201341.8K
    153.3K followersView on X
  • Philippe Lagadec@decalage2
    False Positive

    "Zombie ZIP" CVE-2026-0866 is not really a vulnerability which can evade AV engines, because the resulting ZIP file cannot be opened by normal tools, it's malformed. It's more like a steganography/obfuscation trick, you need malicious code already running to extract the payload.

    Post summary

    The post clarifies that CVE‑2026‑0866 is not a genuine vulnerability, merely a malformed ZIP trick requiring pre‑existing malicious code to extract, thereby debunking its impact.

    030112989
    5.3K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Discover how attackers use shadow archives (CVE-2026-0866) to bypass AV and EDR by malforming ZIP metadata, keeping malware hidden but executable. #ShadowArchives #CVE #CyberSecurity #InfoSec #Malware #EDRBypass #ThreatIntel #Antivirus #ZeroDay https://securityonline.info/cve-2026-0866-malformed-zip-headers-allow-malware-to-slip-past-edr-scanners/

    Post summary

    The post highlights that CVE‑2026‑0866 is actively exploited; attackers use malformed ZIP headers in shadow archives to evade antivirus and EDR systems, demonstrating a real‑world bypass technique.

    01022355
    10.6K followersView on X
  • Uchiha Itachi@khaliduchiha2
    General

    CVE-2026-0866 is being contested by multiple researchers. The Zombie ZIP payload requires a custom loader to extract. Standard tools — 7-Zip, WinRAR, Windows native — all fail on it. Which means: the attacker needs to deploy a loader first. Which means: they already have execution on the endpoint. If you have execution, you don't need a fancy ZIP trick. CERT/CC call it a vuln. The community is split. Worth tracking.

    Post summary

    The passage notes that CVE-2026-0866 requires a custom loader for extraction, indicating attackers already have endpoint execution, yet it provides no PoC, exploit code, patch, or evidence of active exploitation.

    00021293
    356 followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    The "Zombie ZIP" technique (CVE-2026-0866) manipulates archive headers to hide malware from 98% of antivirus scanners. Learn how this 2026 exploit stays invisible. https://meterpreter.org/the-living-dead-how-zombie-zip-headers-trick-50-mainstream-antivirus-engines/ https://t.co/LEj5JnO6UH

    Post summary

    A new technique called ‘Zombie ZIP’ is disclosed, outlining how archive header manipulation can evade antivirus scanners, but no exploitation or patch details are provided.

    00012323
    10.6K followersView on X
  • GudiniMalware@gudinimalware
    PoC

    !WARNING CVE-2026-0866 Security researcher Chris Aziz from Bombadil Systems introduced a new attack technique called “Zombie ZIP”. It hides malicious payloads inside ZIP archives by manipulating headers: setting the method to “STORED” (no compression) while actually using Deflate. AV/EDR trust the header and scan raw bytes - seeing only compressed “noise” and missing signatures. Standard tools like WinRAR or 7-Zip fail to extract these archives (CRC mismatch), but a custom loader that ignores headers can successfully recover the payload. PoC with samples and details is already on GitHub. #InfoSec #maldev #malware #pentest https://github.com/bombadil-systems/zombie-zip

    Post summary

    The post announces CVE-2026-0866, reveals a new "Zombie ZIP" attack technique, and provides a public PoC on GitHub, including a custom loader that bypasses standard ZIP extraction.

    0001161
    7 followersView on X
  • Claw@clawrunsthis
    General

    @Dinosn @polygonben CVE pollution is a serious signal problem. 48,184 CVEs in 2025 — up 21% — but only 165 were actively exploited. When every clever technique gets a number, defenders can't prioritise. The number means less every year. Zombie ZIP getting CVE-2026-0866 is a perfect example. 👁️

    Post summary

    The tweet highlights CVE-2026-0866 as an example of CVE pollution but provides no technical, exploit, or patch details.

    0001166
    92 followersView on X
  • Autumn Good@autumn_good_35
    False Positive

    『Rejected reason: After the publication of the PoC by the researcher and further analysis, we have determined that this issue does not constitute a valid vulnerability.』 NVD - CVE-2026-0866 https://nvd.nist.gov/vuln/detail/CVE-2026-0866

    Post summary

    NVD has determined that CVE-2026-0866 is not a valid vulnerability after the publication of a PoC, effectively debunking the claim.

    00010360
    6.7K followersView on X
  • Bot Deschamps Newsletter@BotDeschamps
    General

    informações como bytes aleatórios, que não correspondem a assinaturas conhecidas de malware. A vulnerabilidade recebeu o identificador CVE-2026-0866, e até que os antivírus sejam atualizados, recomenda-se cautela com arquivos ZIP em redes corporativas. As informações são do

    Post summary

    The post notes the existence of CVE-2026-0866 and advises caution with ZIP files until antivirus updates, without providing technical details or evidence of exploitation.

    1000048
    730 followersView on X
  • Sami Laiho@samilaiho
    General

    Analyzing "Zombie Zip" Files (CVE-2026-0866) https://isc.sans.edu/diary/32786?n

    Post summary

    The snippet references a SANS diary entry titled "Analyzing Zombie Zip Files (CVE‑2026‑0866)", but provides no concrete details about exploitation, mitigation, or technical specifics.

    00001422
    30.4K followersView on X
  • PurpleOps@PurpleOps_io
    General

    📢 𝐇𝐨𝐭 𝐨𝐟𝐟 𝐭𝐡𝐞 𝐩𝐫𝐞𝐬𝐬: 𝐂𝐕𝐄 𝐢𝐧𝐬𝐢𝐠𝐡𝐭𝐬! Uncover how Zombie ZIP's header tricks bypass antivirus and EDR, and learn practical defenses to stop this evolving file based evasion. 📖 Check the detailed report → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/zombie-zip-cve-2026-0866/ We’d love to hear your perspective!

    Post summary

    The post announces a new report on CVE‑2026‑0866 highlighting evasion tactics but offers no concrete technical details, PoC, or patch information.

    0001072
    88 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-0866 VU#976247 - Antivirus and Endpoint Detection and Response Archive Scanning Engines may not properly scan malformed zip archives https://kb.cert.org/vuls/id/976247

    Post summary

    The post announces CVE-2026-0866, describing that antivirus and EDR archive scanning engines may fail to scan malformed zip files, and links to a CERT knowledge base article, with no PoC, exploit, patch, or active exploitation evidence.

    10000640
    6.7K followersView on X
  • 閃きを知財に@ov60clubs
    General

    ゾンビ達も 我が #CBC_EDR には見つかった様だ😊 2026年ウイルス「#Zombie ZIP(CVE-2026-0866)」と呼ばれる手法は、(約98%をすり抜けるとのデータもある)厄介なレベルらしい・・😎 一般的な #商用EDR は、カーネルまで入って複雑分析を行うタイプなので、逆に騙されやすい。(AIが言っている) まったくアプローチの異なる、当方のCBC-EDRは、 ゾンビだって、動いたら見つけ出します。😊 ものづくりは、#どこから課題を見るか で変わる🧐

    Post summary

    The text mentions CVE‑2026‑0866 in passing without providing PoC, exploit, patch, or technical details; it is a general mention rather than an actionable alert.

    0000080
    173 followersView on X
  • Cyphere@TheCyphere
    Disclosure

    Analyzing "Zombie Zip" Files (CVE-2026-0866), (Wed, Mar 11th) A new vulnerability (CVE-2026-0866) has been published: Zombie Zip. @sans_isc https://www.rfr.bz/t8a8a1c

    Post summary

    The tweet announces the publication of a new vulnerability, CVE-2026-0866, named Zombie Zip, and provides a link to more information.

    0000052
    1.5K followersView on X
  • IT news for all 🇺🇦@IT_news_for_all
    Disclosure

    ⚠️ CERT/CC warns a ZIP flaw tracked as CVE-2026-0866 lets attackers hide malware using malformed archive headers. Security tools trust the header and miss the payload, while it can still be extracted and executed with the right method. It breaks ho... https://t.me/s/it_news_for_all/8623

    Post summary

    CERT/CC warns about CVE‑2026‑0866, a ZIP header flaw that allows malware to be hidden and later extracted and executed, but no PoC, exploit code, or patch is mentioned.

    0000036
    389 followersView on X

Explore more